PT-2026-63392 · Nlnet · Unbound

·

CVE-2026-56416

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions prior to 1.25.2
Description A heap buffer overflow occurs when the validator builds the canonical RDATA form for an RRSIG-covered PX, RP, MINFO, or SOA RRset. The system computes the address of the second embedded domain name and passes it to the query dname tolower() function without verifying if a second name exists in the RDATA. An attacker operating a DNSSEC-signed authoritative server can provide a record missing the second domain name, causing query dname tolower() to read stale bytes in the env->scratch buffer. If the msg-buffer-size is lower than the default, this process can read past the end of the heap allocation.
Recommendations Update to version 1.25.2 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92940
CVE-2026-56416
ECHO-537D-A503-AC1E
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound